Description
A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser
No analysis available yet.
Remediation
Vendor Solution
Install Portal for ArcGIS 2022 Security Update 1
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-40783 | A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser |
References
History
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published:
Updated: 2025-04-10T14:58:02.441Z
Reserved: 2022-08-12T00:00:00.000Z
Link: CVE-2022-38190
Updated: 2024-08-03T10:45:52.963Z
Status : Modified
Published: 2022-08-15T21:15:12.320
Modified: 2024-11-21T07:15:58.137
Link: CVE-2022-38190
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD